<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:19:29 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-00070</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-00070</link>
      <description>bdu:2020-00070</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-00070</guid>
    </item>
    <item>
      <title>certfr-2022-avi-570 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-570</link>
      <description>certfr-2022-avi-570</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-570</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-KU61465 — Security fixes for CVE-2015-3254, CVE-2018-10237, CVE-2018-11798, CVE-2018-1320, CVE-2018-20200, CVE-2019-0205, CVE-202…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ku61465</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stargate&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the stargate package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stargate&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the stargate package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ku61465</guid>
    </item>
    <item>
      <title>cnvd-2019-41287</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-41287</link>
      <description>cnvd-2019-41287</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-41287</guid>
    </item>
    <item>
      <title>EUVD-2026-48385</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-48385</link>
      <description>EUVD-2026-48385</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-48385</guid>
    </item>
    <item>
      <title>fkie_cve-2019-0205</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-0205</link>
      <description>&lt;p&gt;In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-0205</guid>
    </item>
    <item>
      <title>GHSA-rj7p-rfgp-852x — Loop with Unreachable Exit Condition in Apache Thrift</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rj7p-rfgp-852x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.thrift:libthrift&lt;/p&gt;
&lt;p&gt;In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.thrift:libthrift&lt;/p&gt;
&lt;p&gt;In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rj7p-rfgp-852x</guid>
    </item>
    <item>
      <title>gsd-2019-0205</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-0205</link>
      <description>gsd-2019-0205</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-0205</guid>
    </item>
    <item>
      <title>msrc_CVE-2019-0205 — In Apache Thrift all versions up to and including 0.12.0 a server or client may run into an endless loop when feed with…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2019-0205</link>
      <description>msrc_CVE-2019-0205</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2019-0205</guid>
    </item>
    <item>
      <title>OESA-2021-1017 — thrift security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1017</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: thrift&lt;/p&gt;
&lt;p&gt;The Apache Thrift software framework for cross-language services development combines a software stack with a code generation engine to build services that work efficiently and seamlessly between C++, Java, Python, and other languages.\r\n\r\n&#13;
Security Fix(es):\r\n\r\n&#13;
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.(CVE-2019-0205)\r\n\r\n&#13;
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.(CVE-2019-0210)\r\n\r\n&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: thrift&lt;/p&gt;
&lt;p&gt;The Apache Thrift software framework for cross-language services development combines a software stack with a code generation engine to build services that work efficiently and seamlessly between C++, Java, Python, and other languages.\r\n\r\n&#13;
Security Fix(es):\r\n\r\n&#13;
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.(CVE-2019-0205)\r\n\r\n&#13;
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.(CVE-2019-0210)\r\n\r\n&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1017</guid>
    </item>
    <item>
      <title>RHSA-2020:0804 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.7 on RHEL 6 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:0804</link>
      <description>&lt;p&gt;thrift: Endless loop when feed with specific input data thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source wildfly: The &amp;#39;enabled-protocols&amp;#39; value in legacy security is not respected if OpenSSL security provider is in use netty: HTTP request smuggling netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;thrift: Endless loop when feed with specific input data thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source wildfly: The &amp;#39;enabled-protocols&amp;#39; value in legacy security is not respected if OpenSSL security provider is in use netty: HTTP request smuggling netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:0804</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2019-0205</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-0205</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: thrift&lt;/p&gt;
&lt;p&gt;In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: thrift&lt;/p&gt;
&lt;p&gt;In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-0205</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0723 — IBM Integration Bus: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0723</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Integration Bus ausnutzen, um Sicherheitsvorkehrungen zu umgehen und einen Denial of Service Zustand herzustellen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Integration Bus ausnutzen, um Sicherheitsvorkehrungen zu umgehen und einen Denial of Service Zustand herzustellen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0723</guid>
    </item>
  </channel>
</rss>
